Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93393— Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream

Quick assessment

Affected
MongoDB Inc. C Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段关于 MongoDB C 驱动中 TLS 传输层堆溢出漏洞的描述,可以翻译如下: 参考译文: 在基于 Windows 平台 TLS 后端编译的 MongoDB C 驱动中,TLS 传输层存在堆缓冲区溢出漏洞。客户端连接的远程端点,或能够冒充或重定向客户端连接的攻击者,可以在处理传入的加密流量时,导致驱动将攻击者提供的数据写到堆分配内存的边界之外。由于受影响的处理发生在应用层认证完成之前,因此无需身份验证或用户交互。成功利用该漏洞可能导致客户端进程中的内存损坏、相邻堆内存泄露,或导致进程终止。 --- 术语与细节

CVSS 8.1 · High EPSS 0.28% · P21

Affected Version Matrix 12

VendorProduct Version RangeStatus
MongoDB Inc. C Driver 2.4.0 affected
2.3.0≤ 2.3.3 affected
2.2.0≤ 2.2.4 affected
2.1.0≤ 2.1.2 affected
2.0.0≤ 2.0.2 affected
1.30.0≤ 1.30.8 affected
1.29.0≤ 1.29.2 affected
1.28.0≤ 1.28.1 affected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93393

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream
Source: CVE Program / CVE List V5
Vulnerability Description
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB Inc. C Driver 2.4.0 -

II. Public POCs for CVE-2026-93393

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93393

登录查看更多情报信息。

Other References for CVE-2026-93393 (1)

Same Patch Batch · MongoDB Inc. · 2026-09-17 · 6 CVEs total

CVE-2026-92756 5.5 MEDIUM Combining encryption settings may disable encryption
CVE-2026-92757 5.5 MEDIUM Malformed connection string may disable field level encryption
CVE-2026-92758 5.5 MEDIUM Logs may collect sensitive information
CVE-2026-93395 5.3 MEDIUM Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()
CVE-2026-93394 3.7 LOW libmongoc SCRAM client nonce-validation bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-93393

No comments yet


Leave a comment